CVE-2025-2371
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 17, 2025
CWE ID 79
Summary
CVE-2025-2371 is a newly identified vulnerability affecting the PHPGurukul Human Metapneumovirus Testing Management System version 1.0. This issue, rated as problematic, impacts an unknown functionality within the /registered-user-testing.php component's Registered Mobile Number Search. The manipulation of the regmobilenumber argument can lead to Cross-Site Scripting (XSS), enabling attackers to inject malicious scripts into a user's web browser. This vulnerability can be exploited remotely, and the exploit has been made public.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.